An AI acceptable-use policy is the single highest-value document a small business can write about AI. It takes an afternoon, it answers the questions staff actually have, and it converts unmanaged tool use into a position the business can defend to a client, an insurer or a regulator.

This guide covers what the policy must contain, the clauses that matter, who should approve it, and how to keep it current. It is part of the Governance, Risk & Data pillar.

A policy that fits on a page is a policy people remember. The objective is compliance, not documentation.


Why write one

The evidence is unambiguous that the gap is common. A 2026 GTIA study found 44% of small businesses have AI acceptable-use policies, which means the majority are already using AI without one. In the same body of research, 24% named data security and compliance as a top barrier to adoption — awareness of the risk without the control to match it.

The exposure is priced. IBM’s Cost of a Data Breach Report 2026 put the global average cost of a breach at a record $4.99 million, up 12%, with organizations under 500 employees averaging $3.31 million. PwC and IBM also reported a 56% rise in AI-driven attacks.

Against that, a one-page policy is inexpensive in every sense. It is also the precondition for scaling anything: no use case should spread beyond its pilot team until the rules exist.


What the policy must cover

Seven sections, and each answers a question staff will ask.

1. Purpose and scope. Who and what the policy applies to — employees, contractors, volunteers — and which tools and activities it covers.

2. Approved tools. An explicit list. A policy that says “approved AI tools” without naming them creates ambiguity, and ambiguity produces unmanaged risk.

3. Permitted and prohibited data. A list of categories rather than a principle. Staff need to know whether a client contract, a personnel file or a pricing sheet can go into a prompt.

4. Verification. The expectation that AI output is a draft, who checks it, and that the check is recorded.

5. Disclosure. When AI use must be communicated — to clients, to customers, internally — and in what form.

6. Accountability and questions. The person who owns the policy and who staff should ask when unsure. Without a named person, the policy is a document rather than a control.

7. Review. A review date, so the policy changes as the tools and the rules do.


The clauses that matter most

Three clauses do most of the work.

The data clause. Written as a list: client confidential information, personal and employee data, regulated records, credentials, and anything under a contractual restriction on processing may not be entered into an unapproved tool. Add the default: where the category is uncertain, treat it as prohibited and ask.

The verification clause. Written as a step rather than a value: AI output is a draft; a named person verifies figures, claims and citations before use; the check is recorded. This is what turns “be careful” into a control.

The disclosure clause. Written proportionately: disclose where material or required; state that a named person verified the output. The second half is more useful to a client than the first.


Who approves it, and who owns it

Two roles, and they are not the same.

  • The owner maintains the policy, keeps the approved-tool list current, and is the person staff ask when they are unsure. The owner does not need to be senior; they need to be reachable and able to change the document.
  • The approver is the executive who signs the policy and owns the exceptions. Approval matters because the policy will eventually constrain someone senior, and only a senior approval survives that test.

A policy owned by nobody and approved by nobody is a draft that happens to have been circulated.


Rolling it out

A policy nobody has read is worse than no policy, because it creates the appearance of control without the substance. Four steps make it real.

  • Circulate it with a short covering note explaining what changed in practice.
  • Walk through the three key clauses in a fifteen-minute session, with examples relevant to the team.
  • Confirm receipt, so the business can show that staff were told.
  • Attach it to the tools — a link in the tool’s bookmark bar, a note in the shared drive — so it is where the work happens.

Where a business wants to go further, a short quiz on the data clause is more effective than a longer document.


Keeping it current

Policies age quickly in AI because the tools, the model capabilities and the regulatory position all move.

  • Review every six months, and after any change in the tools you use.
  • Update the approved-tool list as tools are adopted, retired or re-terms-of-service.
  • Log the changes, with dates, so staff can see what is current.
  • Re-circulate after material change, with the covering note again.

A policy last reviewed eighteen months ago is not a control; it is a historical document.


A worked policy extract

The clauses that do the work, written as they would appear in the policy.

  • Tools. “The following tools are approved for company work: [list]. Any other AI tool may not be used for company work without written approval from [owner].”
  • Data. “The following must never be entered into any AI tool: client confidential information; personal or employee data; regulated financial, health or legal records; credentials; and any material covered by a confidentiality agreement. If you are unsure which category applies, treat the material as prohibited and ask [owner].”
  • Verification. “AI output is a draft. A named person must verify all figures, claims and citations before the output is used, and the check must be recorded.”
  • Disclosure. “Where AI assisted in producing work delivered to a client, disclose that a named person verified the output. Where a contract or rule requires disclosure of AI use, follow it.”

Four clauses, about a page with the scope and review sections. The wording is deliberately ordinary, because the objective is a policy that staff can follow rather than one that impresses a lawyer.

Common mistakes

  • Naming no tools. Ambiguity produces unmanaged use.
  • Writing principles instead of lists. “Sensitive data” is not actionable; a category list is.
  • No owner. Nobody maintains it, and it decays.
  • No verification clause. The control that matters most is missing.
  • A policy nobody read. Circulation and a walkthrough are part of the work, not a follow-up to it.
  • Never reviewed. Tool and regulatory changes render it stale within a year.

Frequently asked questions

What should an AI acceptable-use policy include?

Purpose and scope, an approved-tool list, permitted and prohibited data, the verification expectation, the disclosure position, a named owner and a review date — seven sections on about a page.

How long should an AI policy be?

About a page. Length is not the measure of a policy; whether it is read and applied is.

Who should approve an AI policy?

An executive, because the policy will eventually constrain someone senior. The day-to-day owner can be anyone reachable and able to update the document.

Do we need a policy if only a few staff use AI?

Yes, and especially then, because informal use is the hardest to govern. The policy is also the precondition for extending use beyond a pilot.

Should the policy ban AI tools we have not approved?

It should require approval before use on company work, and prohibit entering the listed data categories into anything unapproved. An outright ban on unapproved tools is usually unenforceable and drives use underground.

How often should an AI policy be reviewed?

Every six months, and after any material change in tools or the regulatory position. Re-circulate after material change.

Can we adapt a template rather than write one?

Yes, and most small businesses should. What matters is that the approved-tool list, the prohibited-data list and the named owner are specific to your business, because those are the parts a template cannot supply.


Next step

Write the seven sections on one page, name an owner and an approver, and circulate it with a walkthrough of the three key clauses. Download the AI Policy Template to start, or book an AI adoption call to review the draft with you.


Sources

  • GTIA (2026): 44% of small businesses have AI acceptable-use policies; 24% cite data security and compliance as a top AI barrier.
  • IBM, Cost of a Data Breach Report 2026 (July 2026): global average breach cost $4.99 million (up 12%); organizations under 500 employees average $3.31 million. PwC/IBM (2026): 56% rise in AI-driven attacks.

Figures are cited from their sources and dated. This article is general information, not legal advice; confirm your specific obligations with qualified counsel.